AI security antitrust coordination exemption

Full Title:
Collaboration on Adversarial Threats and Security Risks Act

Summary#

This bill creates a limited antitrust exemption so non-Federal entities can share information and coordinate steps to reduce certain artificial intelligence (AI) security risks. It says such sharing or coordination is not an antitrust violation if done in good faith and only to address the specified AI security risks. The bill also requires notice to the Assistant Attorney General in the Antitrust Division before some coordinated delays or limits, and it preserves some antitrust protections and court enforcement.

  • Main change: Allows two or more non-Federal entities to exchange information or coordinate actions about covered AI security risks without automatically violating antitrust laws, if those actions are in good faith and for an exclusive security purpose.
  • Permitted coordination with notice: If companies want to coordinate delays or limits on release, deployment, testing, training, or use of AI, they must give written notice to the Assistant Attorney General before doing so.
  • Limits on the exemption: The exemption does not protect price-fixing, market allocation, monopolization, boycotts, or exchange of pricing information.
  • Burden of proof and controls: A company claiming the exemption must prove by a preponderance of the evidence that it acted in good faith and for the exclusive security purpose, and it must have reasonable internal controls to prevent misuse of shared information.
  • DOJ enforcement: The Attorney General may seek injunctions to stop actions that violate antitrust laws or that are likely to increase AI security risks despite their stated purpose.
  • Confidentiality for notices: Notices given to the Assistant Attorney General are protected from public disclosure under certain federal disclosure exemptions and used only for purposes described in the bill.

What it means for you#

  • Businesses and AI developers: You could share sensitive security information with other companies or jointly delay or limit AI releases to reduce specific security risks without automatically triggering antitrust liability. For some coordinated restrictions, you must send a written notice to the Antitrust Division first.
  • Legal teams and compliance officers: You will likely need to document that information sharing and coordination are done “in good faith” and “for the exclusive purpose” of reducing covered AI security risks. You may need to set up or strengthen internal controls to limit use of shared information for other purposes.
  • Companies considering coordinated delays or limits: Before coordinating delays or limiting deployment, you must notify the Assistant Attorney General in writing with details about the risk and the planned restriction.
  • The Department of Justice (Antitrust Division): May receive and review notices and can seek injunctions if it believes actions violate antitrust laws or increase AI security risks.
  • General public and users of AI products: This could mean some AI products or updates are delayed or restricted when companies judge they pose certain security risks. The bill does not itself create new consumer protections or oversight mechanisms beyond these coordination and DOJ review rules.

Expenses#

No publicly available information.

  • The bill does not include a fiscal note or specific cost estimates in the text provided.
  • Possible costs that could follow from the bill (not estimated in the bill text) include:
    • Compliance costs for companies (setting up internal controls, legal review, preparing notices).
    • Administrative and review costs for the Department of Justice to receive and evaluate notices and to litigate injunctions where needed.
    • Legal costs for companies defending the use of the exemption in court, because the company bears the burden of proof.

Proponents' View#

  • The bill appears intended to let companies share sensitive AI security information and coordinate responses that reduce risks, without fear of automatic antitrust liability.
  • It could make it easier to stop or slow the release of AI systems that pose risks of misuse, theft, weaponization, or severe disruption.
  • The notice requirement and DOJ review aim to provide oversight and a record of coordination.
  • Exempting such security-focused cooperation could improve collective ability to identify, test, and mitigate serious AI threats.

Opponents' View#

  • One concern is that the exemption may open the door to anticompetitive coordination that harms competition, even if labeled as security actions.
  • The bill relies on terms like “good faith” and “exclusive purpose,” which are not fully defined in the bill and could be hard to apply consistently.
  • The requirement that companies prove their actions meet the exemption shifts legal burdens and could lead to increased litigation costs.
  • Confidential treatment of notices might hide details of coordination from the public, raising transparency concerns about whether cooperation served security or business interests.
  • It is unclear how the Antitrust Division will review notices in practice, how quickly it would act, or what standards it will apply to decide whether coordination increases security risks.